Endpoint-Assisted FQDN Policy Enforcement via DNS Cache Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security devices face challenges in enforcing Fully Qualified Domain Name (FQDN) access policies due to difficulties in obtaining accurate DNS information, especially when DNS queries are encrypted or resolved differently by endpoint devices, leading to inconsistent security rule enforcement.
Innovation Solution
A network security device obtains DNS information directly or indirectly from managed endpoint devices using an endpoint service that leverages endpoint DNS caches, ensuring accurate FQDN mapping and enabling the enforcement of FQDN access policies, including those with wildcards, by substituting IP addresses with domain names in the security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network security devices use traditional IP address-based security rules, then device compatibility and basic security enforcement are maintained, but the ability to enforce modern FQDN-based security policies is lost
Solution Approach 1:
The patent introduces an intermediary mechanism where the network security device collaborates with endpoint devices to obtain DNS information. The endpoint device acts as a mediator that provides pre-resolved DNS data to the security device, enabling FQDN-based policy enforcement without requiring the security device to perform complex DNS resolution itself.
Solution Approach 2:
The endpoint device performs DNS resolution in advance and caches the results locally before traffic reaches the network security device. This preliminary action eliminates the need for real-time DNS queries at the security device, reducing complexity while enabling FQDN-based security policies.
2Measurement precision
If network security devices perform real-time DNS resolution for FQDN policies, then accurate FQDN mapping can be achieved, but performance degradation and increased latency occur
Solution Approach 1:
DNS resolution is performed in advance by the endpoint device before traffic reaches the network security device. The resolved FQDN mappings are cached and made available to the security device, eliminating real-time DNS lookup delays and maintaining high traffic processing throughput.
Solution Approach 2:
The network security device obtains copies of DNS resolution results from the endpoint device's local cache. Instead of performing independent DNS queries, the security device uses the already-resolved mappings provided by the endpoint, ensuring accuracy while avoiding performance degradation.
3Object-affected harmful factors
If network security devices encrypt DNS queries to protect privacy, then DNS query confidentiality is improved, but the security device's ability to inspect and enforce FQDN policies is reduced
Solution Approach 1:
The system segments the DNS resolution process into two parts: encrypted DNS queries performed by the endpoint device to protect privacy, and unencrypted FQDN mapping data exchange between endpoint and security device for policy enforcement. This segmentation allows both privacy protection and security inspection to coexist.
Solution Approach 2:
The endpoint device acts as an intermediary that receives encrypted DNS queries, resolves them privately, then provides the resolved FQDN mappings to the network security device in an unencrypted form. This intermediary role enables both DNS query confidentiality and FQDN policy enforcement.
4Reliability
If network security devices maintain separate DNS resolution processes, then independent security control is achieved, but inconsistency with endpoint device DNS resolution leads to policy enforcement failures
Solution Approach 1:
The system establishes a feedback mechanism where the network security device receives DNS resolution results from the endpoint device and uses them to enforce security policies. The endpoint device's DNS cache state feeds back to the security device, ensuring consistency between endpoint and security device views of FQDN mappings.
Solution Approach 2:
The patent merges the DNS resolution functionality into the endpoint device while maintaining security control at the network security device. The endpoint device handles DNS resolution and the security device handles policy enforcement, combining both functions in a coordinated manner to achieve consistency and reliability.
Data Source
AI summary
A network security device has at least one Fully Qualified Domain Name (FQDN) access policy that permits traffic to flow to at least one resource associated with at least one FQDN. The network security device receives, from a managed endpoint device, a packet directed to the at least one resource associated with the at least one FQDN. The network security device obtains DNS information associated with the managed endpoint device and, based on the domain name system (DNS) information, substitutes a network address of the at least one resource into the at least one FQDN access policy to open a traffic flow to the at least one resource associated with the at least one FQDN. The network security device then provides the packet to the at least one resource associated with the at least one FQDN.


